Vulnerability Description
A local cross-site scripting (XSS) vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): Aruba AOS-CX firmware: 10.04.xxxx - versions prior to 10.04.3070, 10.05.xxxx - versions prior to 10.05.0070, 10.06.xxxx - versions prior to 10.06.0110, 10.07.xxxx - versions prior to 10.07.0001. Aruba has released upgrades for Aruba AOS-CX devices that address this security vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | Aos-Cx Firmware | >= 10.04.000, < 10.04.3070 |
| Arubanetworks | Cx 6200F | - |
| Arubanetworks | Cx 6300 | - |
| Arubanetworks | Cx 6400 | - |
| Arubanetworks | Cx 8320 | - |
| Arubanetworks | Cx 8325 | - |
| Arubanetworks | Cx 8360 | - |
| Arubanetworks | Cx 8400 | - |
Related Weaknesses (CWE)
References
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-013.txtPatchVendor Advisory
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-013.txtPatchVendor Advisory
FAQ
What is CVE-2021-29148?
CVE-2021-29148 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A local cross-site scripting (XSS) vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series,...
How severe is CVE-2021-29148?
CVE-2021-29148 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-29148?
Check the references section above for vendor advisories and patch information. Affected products include: Arubanetworks Aos-Cx Firmware, Arubanetworks Cx 6200F, Arubanetworks Cx 6300, Arubanetworks Cx 6400, Arubanetworks Cx 8320.